MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
Brief
A now-patched vulnerability in the popular online hide-and-seek game MECCHA CHAMELEON allowed malicious Steam Workshop maps to plant files on a player’s Windows system and achieve delayed remote code execution after a restart.
Security researcher Robbe Van Roey disclosed the issue on September 3, warning that the game’s custom-map functionality exposed a dangerous Unreal Engine audio-recording capability to Blueprint scripts.
The game’s developers addressed the vulnerability in MECCHA CHAMELEON version 4.
- 0, released on August 20. The update is installed automatically before the game launches.
MECCHA CHAMELEON Flaw
MECCHA CHAMELEON relies heavily on community-created maps distributed through the Steam Workshop. In multiplayer lobbies, the host chooses a map, and other participants are prompted to download it before joining the match.
